|
3161
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is …
|
CWE-94
Code Injection
|
CVE-2026-4257
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3162
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the ar…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5157
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3163
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en code-projects Online Food Ordering System 1.0. Afecta a una función desconocida del archivo /form/order.php del componente Order Module. Dicha manipulación del …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5157
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3164
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function i…
|
CWE-285
Improper Authorization
|
CVE-2026-1710
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3165
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin WooPayments: Pagos Integrados de WooCommerce para WordPress es vulnerable a la modificación no autorizada de datos debido a una comprobación de capacidad faltante en la función 'save_upe_ap…
|
CWE-285
Improper Authorization
|
CVE-2026-1710
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3166
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Contact Form by Supsystic para WordPress es vulnerable a la inyección de plantillas del lado del servidor (SSTI) lo que lleva a la ejecución remota de código (RCE) en todas las versiones ha…
|
CWE-94
Code Injection
|
CVE-2026-4257
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3167
|
8.8 |
HIGH
Network
|
-
|
-
|
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_trou…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2026-5130
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3168
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Debugger & Troubleshooter para WordPress era vulnerable a una escalada de privilegios no autenticada en versiones hasta la 1.3.2 inclusive. Esto se debía a que el plugin aceptaba el val…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2026-5130
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3169
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_f…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3170
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Everest Forms Pro para WordPress es vulnerable a ejecución remota de código a través de inyección de código PHP en todas las versiones hasta la 1.9.12, inclusive. Esto se debe a que la func…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|